Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more.
Breach, ransomware, advisory and threat intelligence, classified by LiveThreat and refreshed every half hour. Free members receive the digest and set their own topics.
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more.
Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox. The Rydox marketplace has been active since February 2016; it facilitated over 7,600
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before your SAP ECC migration goes live In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls projects more often …
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and
Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5.
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations.
Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code.
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks.
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief
CISA Taps Regional Directors as Election Advisers Amid Unspent EI-ISAC Funds The U.S. Cybersecurity and Infrastructure Security Agency released a 2026 election security plan offering state and local officials free threat sharing, scanning and advisory support ahead of the midterms, as lawmakers say funding Congress set aside for an election threat-sharing hub remains unspent.
CPU-Based Agreement With Anthropic Will Require Major Cloud Capacity From Akamai San Francisco-based frontier AI lab Anthropic committed $11.6 billion over seven years to Akamai cloud infrastructure for CPU-based AI workloads, giving Boston-area Akamai its largest contract ever and triggering a $5.5 billion capacity buildout ahead of revenue beginning in 2027.
D.C. Circuit says Claude’s built-in restrictions can qualify as a supply chain risk A federal three judge panel gave the U.S. Department of Defense the go-ahead to continue blacklisting Anthropic, a setback in the artificial intelligence giant's bid to take on the Trump administration in court. The ruling may dissuade companies from working with Anthropic.
An Intrusion Last Year May Have Provided Hackers With a Roadmap for OT Cyberattacks U.S. authorities are warning companies that use operational technology to take care when granting online access to third-party integrators or consultants, warning that foreign hackers are actively using such connections as a vector for cyberattacks.
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
Intelligence provided by LiveThreat, a product of a founding sponsor of the association. Each brief links to LiveThreat's analysis and the original source. RSS: Breach & Ransomware Watch Advisories & Threat Intel
Written by the association: what the week's intelligence means for the controls you run.
A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.
Findings from practitioner roundtables on AI governance programs in their first year.
How practitioners are organizing one evidence base to serve buyers and auditors at the same time.
What a site must do when it sees a GPC signal, and how to evidence it.
No membership required. Confirm by email; unsubscribe in one click.